CN103051535B - A kind of data cut-in method, device and data insertion system - Google Patents

A kind of data cut-in method, device and data insertion system Download PDF

Info

Publication number
CN103051535B
CN103051535B CN201210551901.0A CN201210551901A CN103051535B CN 103051535 B CN103051535 B CN 103051535B CN 201210551901 A CN201210551901 A CN 201210551901A CN 103051535 B CN103051535 B CN 103051535B
Authority
CN
China
Prior art keywords
message
subscriber equipment
service
mark
virtual insertion
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201210551901.0A
Other languages
Chinese (zh)
Other versions
CN103051535A (en
Inventor
刘恩慧
胡士辉
于德雷
周天然
李广鹏
任健
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CN201210551901.0A priority Critical patent/CN103051535B/en
Publication of CN103051535A publication Critical patent/CN103051535A/en
Application granted granted Critical
Publication of CN103051535B publication Critical patent/CN103051535B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Abstract

The embodiment of the present invention provides a kind of data cut-in method, device and data insertion system, relates to the communications field, while can meeting the ever-increasing demand to access application of user, reduces the cost of access of subscriber equipment.For a device for network side, comprise concentrator marker, for receiving the first message that subscriber equipment sends, in the mark of the heading encapsulation subscriber equipment of the first message, generating the second message, sending the second message; Transponder, for receiving the second message, determining the Virtual insertion router corresponding with the mark of subscriber equipment, sending the second message to the Virtual insertion router corresponding with the mark of subscriber equipment; The Virtual insertion router corresponding with the mark of subscriber equipment, for receiving the second message; When the second message meets default filtering rule, according to type of service process second message of the second message; According to the second message after the destination address transmission processing of the second message.The embodiment of the present invention is used for subscriber equipment access network.

Description

A kind of data cut-in method, device and data insertion system
Technical field
The present invention relates to the communications field, particularly relate to a kind of data cut-in method, device and data insertion system.
Background technology
Along with the extensive use of cloud computing, the couple in router that enterprise buys needs to increase increasing characteristic to meet the demand of new business, but traditional couple in router equipment, the characteristic update cycle is long, cannot meet the demand of the business renewal that enterprise makes rapid progress.
In prior art, medium-sized and small enterprises or branched structure generally buy couple in router voluntarily, by couple in router access wide area network and internet.Wherein, branch can be connected by wide area network and enterprise headquarters.Along with the business promotion of cloud computing, part medium-sized and small enterprises have purchased privately owned cloud at cloud computing center, MPLSVPN (Multi-ProtocolLabelSwitchingVirtualPrivateNetwork can be passed through, MPLS VPN network) or IPsecVPN (InternetProtocolSecurityVirtualPrivateNetwork, internet protocol fail safe VPN (virtual private network)) and privately owned cloud connect.In addition, medium-sized and small enterprises have a large amount of mobile subscriber, can arrange SSLVPN (SecureSocketsLayerVirtualPrivateNetwork, safe socket layer virtual private network) gateway merit on the access router for mobile employee provides safe long-range access.
But medium-sized and small enterprises or branched structure need to purchase couple in router voluntarily, and purchase cost and maintenance cost are all relatively high.And fixing router device also cannot be upgraded with the popularization of enterprise, needs again to change router device, be equivalent to and add spending to medium-sized and small enterprises or branched structure.Along with the popularization of cloud computing, new application emerges in an endless stream, and fixing business router more cannot adapt to the needs that new access application disposed by medium-sized and small enterprises or branched structure.
Summary of the invention
Embodiments of the invention provide a kind of data cut-in method, device and data insertion system, access process can be carried out to the message of subscriber equipment at network side, meet the ever-increasing demand to access application of user on the one hand, reduce the cost of access of subscriber equipment on the one hand.
For achieving the above object, embodiments of the invention adopt following technical scheme:
First aspect, provides a kind of device for network side, and described device comprises concentrator marker, transponder and at least one Virtual insertion router, wherein:
Described concentrator marker, for receiving the first message that subscriber equipment sends, encapsulating the mark of described subscriber equipment, generating the second message, sending described second message at the heading of described first message;
Described transponder, for receiving described second message, determines the Virtual insertion router corresponding with the mark of described subscriber equipment, sends described second message to the Virtual insertion router corresponding with the mark of described subscriber equipment;
The Virtual insertion router corresponding with the mark of described subscriber equipment, for receiving described second message; When described second message meets default filtering rule, the second message according to the type of service process of described second message; According to described second message after the destination address transmission processing of described second message.
In the implementation that the first is possible, according to first aspect, the Virtual insertion router corresponding with the mark of described subscriber equipment, also for when described second message does not meet default filtering rule, the destination address according to described second message sends described second message.
In the implementation that the second is possible, in conjunction with first aspect and the first possible implementation, described device is implemented as:
The Virtual insertion router corresponding with the mark of described subscriber equipment comprises packet filtering unit, retransmission unit and at least one Service Processing Unit, wherein:
Described packet filtering unit, for receiving described second message;
Described Service Processing Unit, for when described packet filtering unit determines that described second message meets default filtering rule, the second message according to the type of service process of described second message;
Described retransmission unit, for sending described second message after described Service Processing Unit process according to the destination address of described second message.
In the implementation that the third is possible, the implementation possible according to the second, the Virtual insertion router corresponding with the mark of described subscriber equipment also comprises:
Service Control Unit, for receiving the customization request that subscriber equipment sends, at least one type of service that described customization request indicates described subscriber equipment to customize; Different Message processing orders is preset respectively for type of service described in each, to receive to make each described Service Processing Unit and after processing described message, the processing sequence corresponding according to the type of service of described message sends message to the described Service Processing Unit of the next one.
Second aspect, provides a kind of data cut-in method, comprising:
Receive the first message that subscriber equipment sends, encapsulate the mark of described subscriber equipment at the heading of described first message, generate the second message;
Determine the Virtual insertion router corresponding with the mark of described subscriber equipment;
Make the Virtual insertion router corresponding with the mark of described subscriber equipment when described second message meets default filtering rule, the second message according to the type of service process of described second message; According to described second message after the destination address transmission processing of described second message.
In the implementation that the first is possible, according to second aspect, described method also comprises:
Make the Virtual insertion router corresponding with the mark of described subscriber equipment when described second message does not meet default filtering rule, the destination address according to described second message sends described second message.
In the implementation that the second is possible, in conjunction with first aspect or the first possible implementation, described method also comprises:
Receive the customization request that subscriber equipment sends, at least one type of service that described customization request indicates described subscriber equipment to customize; Different Message processing orders is preset respectively for type of service described in each.
The third aspect, provides a kind of data insertion system, comprising:
The above-mentioned device for network side;
Subscriber equipment, for sending the first message to described device, if the destination address of the second message after described device process is described subscriber equipment, then receives described second message that described device sends.
The data cut-in method that the embodiment of the present invention provides, device and data insertion system, the device for network side receives the first message that subscriber equipment sends, and in the mark of the heading encapsulation subscriber equipment of the first message, generates the second message; Determine the Virtual insertion router corresponding with the mark of subscriber equipment, send the second message to the Virtual insertion router corresponding with the mark of subscriber equipment; The Virtual insertion router corresponding with the mark of subscriber equipment receives the second message; When the second message meets default filtering rule, according to type of service process second message of the second message; According to the second message after the destination address transmission processing of the second message.Owing to being provided with multiple Virtual insertion router in the device of network side, the filtration of the message to different user devices, process and forwarding can be realized, therefore user can pass through the router feature needed for device realization of network side, without the need to buying and the entity router of constantly upgrade maintenance oneself purchase again.So, the device that the filtration that script needs carry out in user equipment side, forwarding and process can lead to fortune network side completes, reduce buying and the maintenance cost of the routers of subscriber equipment, and, device due to network side can upgrade in time upgrading, and then meets the ever-increasing demand to access application of user.
Accompanying drawing explanation
In order to be illustrated more clearly in the embodiment of the present invention or technical scheme of the prior art, be briefly described to the accompanying drawing used required in embodiment or description of the prior art below, apparently, accompanying drawing in the following describes is only some embodiments of the present invention, for those of ordinary skill in the art, under the prerequisite not paying creative work, other accompanying drawing can also be obtained according to these accompanying drawings.
The structural representation of the device for network side that Fig. 1 provides for the present embodiment;
The structural representation of the device for network side that Fig. 2 provides for the embodiment of the present invention;
The structural representation of the Virtual insertion router that Fig. 3 provides for another embodiment of the present invention;
The structural representation of the Virtual insertion router that Fig. 4 provides for another embodiment of the present invention;
The data cut-in method schematic flow sheet that Fig. 5 provides for the embodiment of the present invention;
The data cut-in method schematic flow sheet that Fig. 6 provides for another embodiment of the present invention;
The structural representation of the data insertion system that Fig. 7 provides for the present embodiment.
Embodiment
Below in conjunction with the accompanying drawing in the embodiment of the present invention, be clearly and completely described the technical scheme in the embodiment of the present invention, obviously, described embodiment is only the present invention's part embodiment, instead of whole embodiments.Based on the embodiment in the present invention, those of ordinary skill in the art, not making the every other embodiment obtained under creative work prerequisite, belong to the scope of protection of the invention.
The device 10 for network side that the embodiment of the present invention provides, as shown in Figure 1, comprising:
Concentrator marker 101, transponder 102 and at least one Virtual insertion router 103, wherein, concentrator marker 101, for receiving the first message that subscriber equipment 20 sends, in the mark of the heading encapsulation subscriber equipment 20 of the first message, generate the second message, send the second message.
It should be noted that, the mark of the subscriber equipment 20 that concentrator marker 101 encapsulates can according to interface, the VPN (VirtualPrivateNetwork of access, VPN (virtual private network)) tunnel exit or object IP (InternetProtocol, net association) address encapsulates different codings to message; Or the mark of subscriber equipment 20 encapsulation can be the interface of the access of message, vpn tunneling outlet or object IP address etc.Wherein, the interface of access is subscriber equipment 20 interface that first message passes through when sending the first message to network side, and interface can be distinguished according to specific number or mark; Vpn tunneling exports the interface for message process when downlink message and network side send message to subscriber equipment 20, when being generally used for private network, vpn tunneling outlet can be packaged in the header of message by concentrator marker 101, and vpn tunneling outlet also can be distinguished according to specific number or mark; During for public network, concentrator marker 101 can by the header of object IP address encapsulation in message.Only illustrate with above-mentioned scene herein, but do not do any restriction with this.
Transponder 20, encapsulating and the second message sent for receiving concentrator marker 101, determining the Virtual insertion router 103 corresponding with the mark of subscriber equipment 20, sending the second message to the Virtual insertion router 103 corresponding with the mark of subscriber equipment 20.
It should be noted that, along with the popularization for many years of cloud computing, enterprise's mode accepted by renting obtains computer resource and storage resources, therefore enterprise is also easy to accept to replace being bought voluntarily and maintenance entity router by enterprise, to realize the access task of data message by renting virtual router 30.
Subscriber equipment 20 can be rented in advance, namely a Virtual insertion router 103 is customized according to the type of service of the required process of subscriber equipment 20, the corresponding relation of the Virtual insertion router 103 of each subscriber equipment 20 and customization can be stored in the transponder 20 of this Virtual insertion router 103, the second message that transponder 20 receives for each, the mark of the subscriber equipment 20 encapsulated by the header of this second message determines the Virtual insertion router 103 of customization from corresponding relation, and sends this second message to the Virtual insertion router 103 of this customization.
The Virtual insertion router 103 corresponding with the mark of subscriber equipment 20, for receiving the second message; When the second message meets default filtering rule, according to type of service process second message of the second message; According to the second message after the destination address transmission processing of the second message.
It should be noted that, default filtering rule is subscriber equipment 20 static configuration according to access or dynamic-configuration.Generally, the message kind that subscriber equipment 20 sends is a lot, 256 kinds and even more kinds of message can be sent, that is, transponder 20 also can be 256 kinds and even more kinds of to the Secondary Report language class that Virtual insertion router 103 sends, but Virtual insertion router 103 only severally to process wherein a certain or certain, the message of other most of types is not processed, but send the second message according to the destination address of message, wherein, destination address is used to indicate this second message and mails to network side or return subscriber equipment 20; Return the second message as Virtual insertion router 103 to subscriber equipment 20 or send this second message in other devices of network side or equipment.
Further, as shown in Figure 2, device 10 also comprises service controller 104, presets filtering rule for sending to Virtual insertion router 103, as, service controller 104 can send this default filtering rule to the packet filtering unit in Virtual insertion router 103.
It should be noted that, default filtering rule has two kinds, and a kind of is static configuration, and a kind of is dynamic-configuration.The regular particle size of static configuration is thick, automatically can be configured in Virtual insertion router 103 by service controller 104, also can by manually carrying out manual configuration, is the rule that subscriber equipment 20 just sets when accessing.The regular particle size of dynamic-configuration is thinner, second this message of message identification received according to transponder 10 by service controller 104 generates automatically for after the data flow of user, and issue and be configured in Virtual insertion router 103, upgrade the default filtering rule of static configuration.Wherein, transponder 10 after reception second message, can forward the second message to service controller 104.
Exemplary, default filtering rule is that Virtual insertion router 103 is only to TCP (TransmissionControlProtocol, transmission control protocol) message processes, that is, after the Virtual insertion router 103 corresponding with the mark of subscriber equipment 20 receives the second message, when the second message is TCP message, just according to type of service process second message of the second message, again according to the second message after the destination address transmission processing of the second message, as searched corresponding routing table according to the destination address of the second message, and according to routing table instruction transmission second message etc., when second message is non-TCP message, then sending the second message according to the destination address of the second message, as searched the corresponding routing table of destination address in the second message, and forwarding this second message according to routing table instruction.
It should be noted that, Virtual insertion router 103, when processing the second message, can revise destination address, and the destination address as the second message Central Plains instruction sent to subscriber equipment 20 is revised as to another equipment transmission of network side etc.In this case, Virtual insertion router 103 sends this second message according to processing into rear amended destination address to the second message.
The device 10 that the embodiment of the present invention provides, the first message that the device 10 for network side sends for receiving subscriber equipment 20, in the mark of the heading encapsulation subscriber equipment 20 of the first message, generates the second message; Determine the Virtual insertion router 103 corresponding with the mark of subscriber equipment 20, send the second message to the Virtual insertion router 103 corresponding with the mark of subscriber equipment 20; The Virtual insertion router 103 corresponding with the mark of subscriber equipment 20 receives the second message; When the second message meets default filtering rule, according to type of service process second message of the second message; According to the second message after the destination address transmission processing of the second message.Owing to being provided with multiple Virtual insertion router 103 in the device 10 of network side, the filtration of the message to different user devices 20, process and forwarding can be realized, therefore user can realize required router feature by the device 10 of network side, without the need to buying and the entity router of constantly upgrade maintenance oneself purchase again.So, originally the device 10 that the filtration needing to carry out in subscriber equipment 20 side, forwarding and process can lead to fortune network side completes, reduce buying and the maintenance cost of the routers of subscriber equipment 20, and, device 10 due to network side can upgrade in time upgrading, and then meets the ever-increasing demand to access application of user.
Further, for Virtual insertion router 103 corresponding with the mark of subscriber equipment 20 in the device 10 of network side, as shown in Figure 3, packet filtering unit 1031, retransmission unit 1032 and at least one Service Processing Unit 1033 is comprised.
Packet filtering unit 1031, for receiving the second message, Service Processing Unit 1033, for when packet filtering unit 1031 determines that the second message meets default filtering rule, according to type of service process second message of the second message; Retransmission unit 1032, for sending the second message after Service Processing Unit 1033 process according to the destination address of the second message.
It should be noted that, packet filtering unit 1031 is also for receiving the default filtering rule that above-mentioned service controller 104 sends.Wherein, default filtering rule launches in the above-described embodiments, does not repeat them here.
Further, the Virtual insertion router 103 corresponding with the mark of subscriber equipment 20, as shown in Figure 4, also comprises:
Service Control Unit 1034, for receiving the customization request that subscriber equipment 20 sends, at least one type of service that customization request equipment for indicating user 20 customizes; Preset different Message processing order respectively for each type of service, to receive to make each Service Processing Unit 1033 and after processing message, the processing sequence corresponding according to the type of service of message sends message to next Service Processing Unit 1033.
It is worthy of note, Virtual insertion router 103 can comprise routing forwarding subsystem and service process subsystem, forward subsystem and comprise packet filtering unit 1031 and retransmission unit 1032, service process subsystem comprises Service Processing Unit 1033 and Service Control Unit 1034.
It should be noted that, user uses subscriber equipment 20 accesses network side, entry network site as from the service process platform to access operator sends customization request, customizing virtual couple in router 103, wherein, Service Control Unit 1034 is for receiving this customization request and presetting different Message processing orders respectively according at least one type of service that the subscriber equipment 20 of customization request instruction customizes.There is with the Virtual insertion router 103 making this subscriber equipment 20 customize the ability of business needed for this subscriber equipment 20 of process.The business that different Virtual insertion routers 103 can customize for the subscriber equipment 20 that mark is corresponding provides different Business Processing.
Exemplary, the type of service that customization request equipment for indicating user 20 customizes can be as follows: first, with the access service of remote station, as Virtual insertion router 103 and remote station set up MPLSVPN, IPsecVPN or SSLVPN, the business function that service process subsystem can provide is the business such as application acceleration, voice and video, flow analysis; The second, with the access service of cloud data center, as Virtual insertion router 103 and cloud data center set up MPLSVPN, IPsecVPN or SSLVPN, service process subsystem provides the business such as application acceleration, flow analysis; 3rd, with the access service of internet, as Virtual insertion router 103 realizes internet access, service process subsystem provides the business such as web accelerates.4th, provide mobile employee long-range access, the service process subsystem as Virtual insertion router 103 realizes IPsec gateway or SSLVPN gateway, realizes the long-range access of mobile subscriber.
It is worthy of note, Service Control Unit 1034 presets for each type of service the order that different Service Processing Units 1033 processes message respectively, as, to being directed to type of service A, the Message processing order preset is from Service Processing Unit A to Service Processing Unit M, retransmission unit 1032 is sent to again by Service Processing Unit M, so, if the type of service in the second message is type of service A, then first according to this type of service A, the second message is sent to Service Processing Unit A by packet filtering unit 1031, according to this type of service A, the second message is sent to Service Processing Unit M by Service Processing Unit A again, finally according to this type of service A, the second message is sent to retransmission unit 1032 by Service Processing Unit M.
Exemplary, after the second message of packet filtering unit 1031 transmission received by transponder 20, judge whether the second message meets default filtering rule, if the second message meets default filtering rule, then determine to be forwarded to a certain Service Processing Unit 1033 according to the type of service of the second message, it should be noted that, packet filtering unit 1031 and Service Processing Unit 1033 all can be resolved the second message received, in second message, special sign position has this second message for type of service, the processing sequence that packet filtering unit 1031 and Service Processing Unit 1033 can be determined according to type of service according to Service Control Unit 1034, determine the second message be forwarded to some Service Processing Units 1033 or be forwarded to retransmission unit 1032.As, the type of service of the second message is application acceleration process, it is Service Processing Unit B to Service Processing Unit S that Service Control Unit 1034 presets different Message processing orders, again to Service Processing Unit H, so, second message is first sent to Service Processing Unit B according to application acceleration process by packet filtering unit 1031, according to application acceleration process, the second message is sent to Service Processing Unit S by Service Processing Unit B again, according to application acceleration process, the second message is sent to Service Processing Unit H by Service Processing Unit S again, by Service Processing Unit H, the second message is sent to retransmission unit 1032.Finally, by retransmission unit 1032 according to the second message after the destination address transmission processing of the second message, when destination address is subscriber equipment 20, the second message after application acceleration is sent to subscriber equipment 20;
If the second message does not meet default filtering rule, then the second message can be sent to retransmission unit 1032, by retransmission unit 1032 according to the second message after the destination address transmission processing of the second message, when destination address is network equipment M, the second message is sent to network equipment M.
It should be noted that, in actual applications, Virtual insertion router 103 can forward on subsystem at operator's existing route increases the formation of above-mentioned service process subsystem, the access service of process enterprise.Wherein, routing forwarding subsystem is made up of carrier routers, and service process subsystem is made up of the computing unit of generic server or router.On routing forwarding subsystem, fictionalizing the exclusive packet filtering unit 1031 of enterprise and retransmission unit 1032, as realized retransmission unit 1032 by vpn technology, being responsible for the forwarding of enterprise's message with redirected.Fictionalize the exclusive Service Control Unit of enterprise 1034 and Service Processing Unit 1033 at service process subsystem, be responsible for the process of access service, such as fire compartment wall, application acceleration, flow analysis etc.
It should be noted that, Virtual insertion router 103 can comprise forwarding subsystem and service process subsystem, wherein, forward subsystem and comprise packet filtering unit 1031 and retransmission unit 1032, service process subsystem comprises Service Processing Unit 1033 and Service Control Unit 1034.Virtual insertion router 103 also can not comprise forwarding subsystem and service process subsystem, but comprises packet filtering unit 1031, retransmission unit 1032, Service Processing Unit 1033 and Service Control Unit 1034.
The embodiment of the present invention Virtual insertion router 103 corresponding with the mark of subscriber equipment 20 receives the second message; When the second message meets default filtering rule, according to type of service process second message of the second message; According to the second message after the destination address transmission processing of the second message.Owing to being provided with multiple Virtual insertion router 103 in the device 10 of network side, the filtration of the message to different user devices 20, process and forwarding can be realized, therefore user can realize required router feature by the device 10 of network side, without the need to buying and the entity router of constantly upgrade maintenance oneself purchase again.So, originally the device 10 that the filtration needing to carry out in subscriber equipment 20 side, forwarding and process can lead to fortune network side completes, reduce buying and the maintenance cost of the routers of subscriber equipment 20, and, device 10 due to network side can upgrade in time upgrading, and then meets the ever-increasing demand to access application of user.
The data cut-in method that the embodiment of the present invention provides, as shown in Figure 5, comprising:
S101, the first message sent for the device reception subscriber equipment of network side, in the mark of the heading encapsulation subscriber equipment of the first message, generate the second message.
S102, determine the Virtual insertion router corresponding with the mark of subscriber equipment for the device of network side.
It should be noted that, device for network side can comprise concentrator marker and transponder, wherein, the first message that concentrator marker sends for receiving subscriber equipment, in the mark of the heading encapsulation subscriber equipment of the first message, generates the second message, the second message is sent to transponder, transponder then for receiving the second message, determines the Virtual insertion router corresponding with the mark of subscriber equipment, sends the second message to the Virtual insertion router corresponding with the mark of subscriber equipment.
S103, make the Virtual insertion router corresponding with the mark of subscriber equipment when the second message meets default filtering rule for the device of network side, according to type of service process second message of the second message; According to the second message after the destination address transmission processing of the second message.
Further, subscriber equipment can customizing virtual couple in router in advance, namely before the device for network side receives the first message of subscriber equipment transmission, Virtual insertion router first can receive the customization request that subscriber equipment sends, at least one type of service of customization request equipment for indicating user customization; Different Message processing orders is preset respectively for each type of service.The process of customization and how preset different Message processing by type of service and sequentially describe in the above-described embodiments, does not repeat them here.
It is worthy of note, make the Virtual insertion router corresponding with the mark of subscriber equipment when the second message meets default filtering rule, before type of service process second message according to the second message, the default filtering rule that service controller sends can also be received, wherein, service controller belongs to the device of network side, and the default filtering rule that service controller issues can dynamically or static configuration.
Exemplary, for in the device of network side, the Virtual insertion router corresponding with the mark of subscriber equipment can be provided with routing forwarding subsystem and service process subsystem, a Service Control Unit and multiple Service Processing Unit can be provided with in service process subsystem, Service Control Unit can distribute multiple Business Processing order according to the type of service of customization, and Service Processing Unit can follow one of them Business Processing sequential processes second message according to the type of service of the second message.
It is worthy of note, after the process of the device for network side, the destination address of the second message may change, and the second message is sent to other devices of network side or subscriber equipment by the destination address in this case finally should determined according to the second message.
The data cut-in method that the embodiment of the present invention provides, the device for network side receives the first message that subscriber equipment sends, and in the mark of the heading encapsulation subscriber equipment of the first message, generates the second message; Determine the Virtual insertion router corresponding with the mark of subscriber equipment, send the second message to the Virtual insertion router corresponding with the mark of subscriber equipment; The Virtual insertion router corresponding with the mark of subscriber equipment receives the second message; When the second message meets default filtering rule, according to type of service process second message of the second message; According to the second message after the destination address transmission processing of the second message.Owing to being provided with multiple Virtual insertion router in the device of network side, the filtration of the message to different user devices, process and forwarding can be realized, therefore user can pass through the router feature needed for device realization of network side, without the need to buying and the entity router of constantly upgrade maintenance oneself purchase again.So, the device that the filtration that script needs carry out in user equipment side, forwarding and process can lead to fortune network side completes, reduce buying and the maintenance cost of the routers of subscriber equipment, and, device due to network side can upgrade in time upgrading, and then meets the ever-increasing demand to access application of user.
Further, as shown in Figure 6, data cut-in method after step s 102, also comprises:
S104, making the Virtual insertion router corresponding with the mark of subscriber equipment when not meeting default filtering rule when the second message for the device of network side, sending the second message according to the destination address of the second message.
The data cut-in method that the embodiment of the present invention provides, the device for network side receives the first message that subscriber equipment sends, and in the mark of the heading encapsulation subscriber equipment of the first message, generates the second message; Determine the Virtual insertion router corresponding with the mark of subscriber equipment, send the second message to the Virtual insertion router corresponding with the mark of subscriber equipment; The Virtual insertion router corresponding with the mark of subscriber equipment receives the second message; When the second message meets default filtering rule, according to type of service process second message of the second message; According to the second message after the destination address transmission processing of the second message.Owing to being provided with multiple Virtual insertion router in the device of network side, the filtration of the message to different user devices, process and forwarding can be realized, therefore user can pass through the router feature needed for device realization of network side, without the need to buying and the entity router of constantly upgrade maintenance oneself purchase again.So, the device that the filtration that script needs carry out in user equipment side, forwarding and process can lead to fortune network side completes, reduce buying and the maintenance cost of the routers of subscriber equipment, and, device due to network side can upgrade in time upgrading, and then meets the ever-increasing demand to access application of user.
The data insertion system 1 that the embodiment of the present invention provides, as shown in Figure 7, comprising:
The device 10 for network side that above-described embodiment provides;
Subscriber equipment 20, for sending the first message to device, if the destination address of the second message after device process is subscriber equipment, then the second message of receiving system transmission.
It is worthy of note, except the device 10 of network side also should be provided with other device in data insertion system 1, if to make device that the destination address of the second message after processing is other time, device 10 sends the second message to other devices.
The method that above-described embodiment all can be used to provide for the device 10 of network side and Virtual insertion router 103 in notebook data connecting system 1 carries out work, and the structure of the device 10 of network side and Virtual insertion router 103 is identical with the structure that above-described embodiment provides, and does not repeat them here.
The data insertion system 1 that the embodiment of the present invention provides, the first message that the device 10 for network side sends for receiving subscriber equipment 20, in the mark of the heading encapsulation subscriber equipment 20 of the first message, generates the second message; Determine the Virtual insertion router 103 corresponding with the mark of subscriber equipment 20, send the second message to the Virtual insertion router 103 corresponding with the mark of subscriber equipment 20; The Virtual insertion router 103 corresponding with the mark of subscriber equipment 20 receives the second message; When the second message meets default filtering rule, according to type of service process second message of the second message; According to the second message after the destination address transmission processing of the second message.Owing to being provided with multiple Virtual insertion router 103 in the device 10 of network side, the filtration of the message to different user devices 20, process and forwarding can be realized, therefore user can realize required router feature by the device 10 of network side, without the need to buying and the entity router of constantly upgrade maintenance oneself purchase again.So, originally the device 10 that the filtration needing to carry out in subscriber equipment 20 side, forwarding and process can lead to fortune network side completes, reduce buying and the maintenance cost of the routers of subscriber equipment 20, and, device 10 due to network side can upgrade in time upgrading, and then meets the ever-increasing demand to access application of user.
One of ordinary skill in the art will appreciate that: all or part of step realizing said method embodiment can have been come by the hardware that program command is relevant, aforesaid program can be stored in a computer read/write memory medium, this program, when performing, performs the step comprising said method embodiment; And aforesaid storage medium comprises: ROM, RAM, magnetic disc or CD etc. various can be program code stored medium.
The above; be only the specific embodiment of the present invention, but protection scope of the present invention is not limited thereto, is anyly familiar with those skilled in the art in the technical scope that the present invention discloses; change can be expected easily or replace, all should be encompassed within protection scope of the present invention.Therefore, protection scope of the present invention should be as the criterion with the protection range of described claim.

Claims (11)

1. for a device for network side, it is characterized in that, described device comprises concentrator marker, transponder and at least one Virtual insertion router, wherein:
Described concentrator marker, for receiving the first message that subscriber equipment sends, encapsulating the mark of described subscriber equipment, generating the second message, sending described second message at the heading of described first message;
Described transponder, for receiving described second message, determines the Virtual insertion router corresponding with the mark of described subscriber equipment, sends described second message to the Virtual insertion router corresponding with the mark of described subscriber equipment;
The Virtual insertion router corresponding with the mark of described subscriber equipment, for receiving described second message; When described second message meets default filtering rule, the second message according to the type of service process of described second message; According to described second message after the destination address transmission processing of described second message; Wherein, described destination address is used to indicate described second message and mails to network side or return described subscriber equipment.
2. device according to claim 1, is characterized in that,
The Virtual insertion router corresponding with the mark of described subscriber equipment, also for when described second message does not meet default filtering rule, the destination address according to described second message sends described second message.
3. device according to claim 1 and 2, is characterized in that, the Virtual insertion router corresponding with the mark of described subscriber equipment comprises packet filtering unit, retransmission unit and at least one Service Processing Unit, wherein:
Described packet filtering unit, for receiving described second message;
Described Service Processing Unit, for when described packet filtering unit determines that described second message meets default filtering rule, the second message according to the type of service process of described second message;
Described retransmission unit, for sending described second message after described Service Processing Unit process according to the destination address of described second message.
4. device according to claim 3, is characterized in that, the Virtual insertion router corresponding with the mark of described subscriber equipment also comprises:
Service Control Unit, for receiving the customization request that subscriber equipment sends, at least one type of service that described customization request indicates described subscriber equipment to customize; Different Message processing orders is preset respectively for type of service described in each, to receive to make each described Service Processing Unit and after processing described message, the processing sequence corresponding according to the type of service of described message sends message to the described Service Processing Unit of the next one.
5. device according to claim 3, is characterized in that, described device also comprises service controller;
Described packet filtering unit is also for receiving the default filtering rule that described service controller sends.
6. the device according to claim 1 or 2 or 4 or 5, is characterized in that,
The interface being designated the access of described message of described subscriber equipment, VPN (virtual private network) vpn tunneling export or object net association IP address.
7. a data cut-in method, is characterized in that, comprising:
Receive the first message that subscriber equipment sends, encapsulate the mark of described subscriber equipment at the heading of described first message, generate the second message;
Determine the Virtual insertion router corresponding with the mark of described subscriber equipment;
Make the Virtual insertion router corresponding with the mark of described subscriber equipment when described second message meets default filtering rule, the second message according to the type of service process of described second message; According to described second message after the destination address transmission processing of described second message; Wherein, described destination address is used to indicate described second message and mails to network side or return described subscriber equipment.
8. method according to claim 7, is characterized in that, described determine the Virtual insertion router corresponding with the mark of described subscriber equipment after, also comprise:
Make the Virtual insertion router corresponding with the mark of described subscriber equipment when described second message does not meet default filtering rule, the destination address according to described second message sends described second message.
9. the method according to claim 7 or 8, is characterized in that, before the first message that described reception subscriber equipment sends, also comprises:
Receive the customization request that subscriber equipment sends, at least one type of service that described customization request indicates described subscriber equipment to customize; Different Message processing orders is preset respectively for type of service described in each.
10. the method according to claim 7 or 8, is characterized in that, Virtual insertion router corresponding to the mark of described and described subscriber equipment also comprises before receiving described second message:
Receive the default filtering rule that service controller sends.
11. 1 kinds of data insertion systems, is characterized in that, comprising:
The device for network side described in any one of claim 1 to 6;
Subscriber equipment, for sending the first message to described device, if the destination address of the second message after described device process is described subscriber equipment, then receives described second message that described device sends.
CN201210551901.0A 2012-12-18 2012-12-18 A kind of data cut-in method, device and data insertion system Active CN103051535B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201210551901.0A CN103051535B (en) 2012-12-18 2012-12-18 A kind of data cut-in method, device and data insertion system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201210551901.0A CN103051535B (en) 2012-12-18 2012-12-18 A kind of data cut-in method, device and data insertion system

Publications (2)

Publication Number Publication Date
CN103051535A CN103051535A (en) 2013-04-17
CN103051535B true CN103051535B (en) 2016-01-27

Family

ID=48064040

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201210551901.0A Active CN103051535B (en) 2012-12-18 2012-12-18 A kind of data cut-in method, device and data insertion system

Country Status (1)

Country Link
CN (1) CN103051535B (en)

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104380658B (en) 2013-04-28 2018-06-05 华为技术有限公司 Flow classifier, business route flip-flop, the method and system of Message processing
CN103634211A (en) * 2013-12-03 2014-03-12 网神信息技术(北京)股份有限公司 Data processing method and device for user network edge routers
CN105337902A (en) * 2015-11-17 2016-02-17 福建星网锐捷网络有限公司 Network outlet device, network outlet system and network outlet message processing method
CN108206772A (en) * 2016-12-20 2018-06-26 中兴通讯股份有限公司 A kind of dispatching method, system and controller
CN109922005B (en) * 2017-12-13 2022-08-19 中兴通讯股份有限公司 Load sharing method, device and system and computer readable storage medium
CN110022250B (en) * 2018-01-10 2021-11-12 中兴通讯股份有限公司 Service processing method, terminal and computer storage medium
CN110635986B (en) * 2018-06-25 2021-11-16 ***通信有限公司研究院 Network access method and equipment
CN112333221B (en) * 2019-08-05 2023-09-12 迈普通信技术股份有限公司 Network system, method and communication equipment for centralized processing of network service

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1471275A (en) * 2002-07-23 2004-01-28 ��Ϊ�������޹�˾ Enterprise external virtual special network system and method using virtual router structure
CN102202045A (en) * 2011-03-09 2011-09-28 深圳市同洲电子股份有限公司 Method, system and device for realizing Internet access in broadcast television network
CN102387061A (en) * 2011-10-21 2012-03-21 华为技术有限公司 Method, device and system for accessing VPC (virtual private cloud) to VPN (virtual private network)

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7574495B1 (en) * 2000-09-13 2009-08-11 Fortinet, Inc. System and method for managing interworking communications protocols

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1471275A (en) * 2002-07-23 2004-01-28 ��Ϊ�������޹�˾ Enterprise external virtual special network system and method using virtual router structure
CN102202045A (en) * 2011-03-09 2011-09-28 深圳市同洲电子股份有限公司 Method, system and device for realizing Internet access in broadcast television network
CN102387061A (en) * 2011-10-21 2012-03-21 华为技术有限公司 Method, device and system for accessing VPC (virtual private cloud) to VPN (virtual private network)

Also Published As

Publication number Publication date
CN103051535A (en) 2013-04-17

Similar Documents

Publication Publication Date Title
CN103051535B (en) A kind of data cut-in method, device and data insertion system
US9602307B2 (en) Tagging virtual overlay packets in a virtual networking system
CN102238230B (en) Method and system for offloading tunnel packet processing in cloud computing
CN102255903B (en) Safety isolation method for virtual network and physical network of cloud computing
CN104320350B (en) Method and system for providing fiduciary flow control
CN104636184A (en) Deploying method, device and equipment of instances of virtual machine
CN104995880A (en) Quantized congestion notification in a virtual networking system
CN104052789A (en) Load balancing for a virtual networking system
CN104038401A (en) Interoperability for distributed overlay virtual environments
CN106576074A (en) Routing rule acquisition method, device and system
US10481921B2 (en) Cloud platform, application running method, and access network unit
CN103067416A (en) Virtual private cloud (VPC) access authentication method and correlation apparatus
CN102845123A (en) Virtual private cloud connection method and tunnel proxy server
CN105610675A (en) Creating method and device of virtual VPN gateway
CN105577632A (en) Secure network access method based on network isolation and terminal
WO2014079335A1 (en) Ip packet processing method, apparatus and network system
CN105323310A (en) Network communication method, device and network attached storage device
CN103780467A (en) Communication connection method, communication device and communication system
US10362120B2 (en) Distributed gateways with centralized data center for high throughput satellite (HTS) spot beam network
CN108141384A (en) The automatic arranging of LISP two mobility networks
CN110089078A (en) The method and apparatus of business transponder via dynamic coverage network is provided
CN103703741A (en) Method for disseminating application distribution, terminal and server
CN112105074B (en) MEC-based access flow diversion system and method
CN102164150B (en) Method, device, server and system for delivering strategies
CN103716378A (en) Method for on-line migration of virtual machine in wide area network under future network serval

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant